Splunk Search

incremental value

DataOrg
Builder

I have sequence no of to populate . first column is the sequence of no and answers need to like in the second column

for Example
value value to populate
10 1
10 1
10 1
15 2
15 2
10 3

0 Karma
1 Solution

HiroshiSatoh
Champion

If increment is added for every NO ...

(your search)| streamstats sum(value)  by no

View solution in original post

HiroshiSatoh
Champion

If increment is added for every NO ...

(your search)| streamstats sum(value)  by no

DataOrg
Builder

its not sum.
we need to have a sequence of no if value are same we need to mark it as 1 . if current sequence changes to other set of no. we need to increase the value by 1

0 Karma

HiroshiSatoh
Champion

How's this?

 (your search)
|autoregress p=1 no as no_old
|eval change=if(no=no_old,0,1)
| streamstats sum(change) as inc_value
|table no inc_value
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...